CVE-2005-3532
CVE-2005-3532
authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=211920http://secunia.com/advisories/17919http://secunia.com/advisories/17999https://exchange.xforce.ibmcloud.com/vulnerabilities/23532https://usn.ubuntu.com/226-1/http://www.debian.org/security/2005/dsa-917http://www.securityfocus.com/bid/15771/